3 ms·
Wait, what?? There's an invisible DNS server running inside your VPC? I get what you're saying wrt cached DNS lookups but this seems wild.
by ajsharp 7y ago
Wait, what?? There's an invisible DNS server running inside your VPC? I get what you're saying wrt cached DNS lookups but this seems wild.
- ra1n85 7y agoIt's a DNS resolver that runs on the hypervisor hosting every instance.
- tbrock 7y agoYes and they limit you to throwing 1024 packets per second per network interface at it. Of course you could run your own dns cache per host/pod whatever.
- cocire 7y agoyou've got me so curious, could you please point me to the aws docs?
- tbrock 7y agoIt’s the first thing on google when you google “aws dns vpc limits” but sure: https://docs.aws.amazon.com/vpc/latest/userguide/vpc-dns.html#vpc-dns-limits https://docs.aws.amazon.com/vpc/latest/userguide/vpc-dns.htm...
- res0nat0r 7y agoYour VPC has a DNS server at .2 of your VPC CIDR block that is mounted via loopback on the dom0 and exposed to your VPC to let you do lookups via their DNS infra. https://aws.amazon.com/premiumsupport/knowledge-center/vpc-enable-private-hosted-zone/ https://aws.amazon.com/premiumsupport/knowledge-center/vpc-e...
- andreareina 7y agoThis allows them to hand out private network addresses (IIRC they use 172.x.x.x) when the DNS query happens from within AWS.
- rconti 7y ago"Invisible?" I mean, everyone who builds AWS infra, even just single ec2 instances, is aware of it. It's definitely possible that application engineers aren't aware, though.